Network attack identification method, device, equipment, medium and product
By combining historical request information and unique identifiers from user terminals, a pre-trained attack identification model is used for secondary identification, which solves the problem of insufficient identification of covert or hybrid attacks in cloud computing networks and achieves a more comprehensive attack identification effect.
Patent Information
- Application Number
- CN202511527030.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-24
- Publication Date
- 2025-12-12
AI Technical Summary
Existing technologies cannot fully cover the various network attacks in cloud computing networks, especially covert or hybrid attacks, leading to inaccurate identification results.
By determining the user terminal's historical request history and unique identification information, and combining this with a pre-trained attack identification model, a secondary network attack identification is performed to identify whether the user terminal is an ordinary or malicious user terminal.
It achieves comprehensive identification of multiple attack types, avoids missing covert or hybrid attacks, and improves the accuracy of attack identification.
Smart Images

Figure CN121125328A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and in particular to a method, apparatus, device, medium and product for identifying network attacks. Background Technology
[0002] The rapid development of cloud computing technology has greatly facilitated data storage, processing, and applications, but it has also brought unprecedented cybersecurity challenges. Currently, cloud computing networks face various cyberattacks, such as botnets, DDoS attacks, and brute-force attacks.
[0003] To ensure the security and stability of cloud computing networks and thus provide more reliable and secure services to businesses and individuals, existing technologies have proposed numerous attack identification and security protection methods for cloud computing networks, such as black hole routing, rate limiting, and web application firewalls.
[0004] However, these methods are typically designed and optimized only for specific types of attacks. A single, targeted identification method cannot comprehensively cover all possible attack types and is prone to missing some covert or hybrid attacks. Some DDoS attack detection methods rely primarily on the IP address of the request-sending server for identification and interception. If an attacker simultaneously rents multiple cloud servers and launches attacks from different IP addresses, they can bypass defense mechanisms based on a single IP address, making it impossible to effectively identify and prevent distributed attack behavior. Summary of the Invention
[0005] This invention provides a network attack identification method, apparatus, device, medium, and product to achieve identification of multiple attack types and ensure more accurate attack identification results.
[0006] According to a first aspect of the present invention, a method for identifying network attacks is provided, comprising:
[0007] When a user request is received from a user terminal, the historical request history of the user terminal is determined.
[0008] Based on the historical request information, the unique identifier information of the user terminal, and the historical service request information, the identity verification result and the terminal evaluation result are determined. The terminal evaluation result includes evaluating the user terminal as an ordinary user terminal or a malicious user terminal.
[0009] Based on the pre-trained attack identification model, a secondary network attack identification is performed on the user terminal whose authentication result is passed and the ordinary user terminal to determine the identification result.
[0010] According to a second aspect of the present invention, a network attack identification device is provided, comprising:
[0011] The request acquisition module is used to determine the historical request status of the user terminal when it receives a user request sent by the user terminal.
[0012] The first determining module is used to determine the identity verification result and the terminal evaluation result based on the historical request information, the unique identification information of the user terminal and the historical service request information. The terminal evaluation result includes evaluating the user terminal as an ordinary user terminal or a malicious user terminal.
[0013] The second determining module is used to perform secondary network attack identification on the user terminal whose authentication result is passed and the ordinary user terminal based on the pre-trained attack identification model, and to determine the identification result.
[0014] According to a third aspect of the present invention, an electronic device is provided, the electronic device comprising:
[0015] At least one processor; and
[0016] A memory communicatively connected to the at least one processor; wherein,
[0017] The memory stores a computer program that can be executed by the at least one processor, which enables the at least one processor to perform the network attack identification method according to any embodiment of the present invention.
[0018] According to a fourth aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions, the computer instructions being configured to cause a processor to execute and implement the network attack identification method according to any embodiment of the present invention.
[0019] According to a fifth aspect of the present invention, embodiments of the present invention also provide a computer program product, the computer program product including a computer program, which, when executed by a processor, implements the network attack identification method of any embodiment of the present invention.
[0020] The technical solution of this invention involves determining the user terminal's historical request history upon receiving a user request; determining the authentication result and terminal evaluation result based on the historical request history, the user terminal's unique identifier, and historical service request information. The terminal evaluation result includes classifying the user terminal as a normal user terminal or a malicious user terminal; and performing secondary network attack identification on user terminals with successful authentication and normal user terminals based on a pre-trained attack identification model to determine the identification result. This achieves more comprehensive attack type identification, avoids missing some covert or hybrid attacks, and thus ensures more accurate attack identification results.
[0021] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description
[0022] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0023] Figure 1 This is a flowchart of a network attack identification method provided in Embodiment 1 of the present invention;
[0024] Figure 2 This is a schematic diagram of the structure of a network attack identification device according to Embodiment 2 of the present invention;
[0025] Figure 3 This is a schematic diagram of the structure of an electronic device that implements an embodiment of the present invention. Detailed Implementation
[0026] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0027] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0028] Example 1
[0029] Figure 1This is a flowchart illustrating a network attack identification method provided in Embodiment 1 of the present invention. This embodiment is applicable to network attack identification of user terminals by cloud servers. The method can be executed by a network attack identification device, which can be implemented in hardware and / or software and can be configured in an electronic device. Figure 1 As shown, the method includes:
[0030] S110. When a user request is received from a user terminal, determine the user terminal's historical request history.
[0031] In this embodiment, a user terminal can be understood as a terminal that requires services from a cloud server. A user request can be understood as a request to the cloud server to request services. Historical request information is used to indicate whether the user terminal is accessing the cloud server for the first time.
[0032] Specifically, when the cloud server's processor detects a user request sent by a user terminal, it can first determine whether the user terminal is requesting cloud server services for the first time and obtain historical request information.
[0033] S120. Based on historical request information, the unique identifier of the user terminal, and historical service request information, determine the authentication result and the terminal evaluation result. The terminal evaluation result includes evaluating the user terminal as an ordinary user terminal or a malicious user terminal.
[0034] In this embodiment, the unique identifier information is used to represent the unique code of the user terminal. Historical service request information can be understood as information containing the user terminal's historical requests and access history. Authentication result can be understood as the verification result used to represent whether the user terminal's identity is genuine. Terminal evaluation result is used to represent the evaluation result of whether the user terminal poses a risk.
[0035] Specifically, the processor can categorize user terminals into first-time and non-first-time requesters based on historical request information. For first-time requesters, the processor can authenticate the user terminal using unique identification information to obtain an authentication result. For non-first-time requesters, the processor can assess the user terminal's identity and risk level based on historical service request information, obtaining an authentication result set and a terminal evaluation result.
[0036] S130. Based on the pre-trained attack identification model, perform secondary network attack identification on user terminals with successful authentication results and ordinary user terminals, and determine the identification results.
[0037] In this embodiment, the pre-trained attack identification model can be understood as a trained neural network model used for identifying or classifying attack behaviors. The identification result can be understood as the identification result used to characterize whether the user terminal exhibits attack behavior.
[0038] Specifically, to prevent missed identifications, the processor can input the access behavior information of user terminals whose authentication results are not passed, as well as ordinary user terminals, into the pre-trained attack identification model, and use the model output as the identification result.
[0039] The technical solution of this invention involves determining the user terminal's historical request history upon receiving a user request; determining the authentication result and terminal evaluation result based on the historical request history, the user terminal's unique identifier, and historical service request information. The terminal evaluation result includes classifying the user terminal as a normal user terminal or a malicious user terminal; and performing secondary network attack identification on user terminals with successful authentication and normal user terminals based on a pre-trained attack identification model to determine the identification result. This achieves more comprehensive attack type identification, avoids missing some covert or hybrid attacks, and thus ensures more accurate attack identification results.
[0040] Furthermore, based on the above embodiments, the steps of determining the authentication result and terminal evaluation result according to historical request information, the unique identifier information of the user terminal, and historical service request information may include:
[0041] If the historical request is the first service request, then the user terminal's unique identifier is used for authentication to determine the authentication result. If the historical request is not the first service request, then the historical service request information is used to determine the preliminary assessment result. For the first user terminal whose preliminary assessment result is a normal terminal, the historical session key and unique identifier of the first user terminal are used for authentication to obtain the authentication result. For the second user terminal whose preliminary assessment result is suspected of being malicious, the final verification is performed to obtain the terminal assessment result.
[0042] In this embodiment, the first service request can be understood as the first time a service request is sent to the processor. Subsequent service requests indicate that service requests have been sent previously. The preliminary evaluation result can be understood as an evaluation result used to characterize whether the user terminal exhibits any attack behavior. The first user terminal is a normal terminal. The second user terminal is a suspected malicious user terminal and requires further confirmation.
[0043] Specifically, if the historical request is for the first service request, the processor can perform authentication based on the user terminal's unique identifier and the verification platform to determine the authentication result. If the historical request is not for the first service request, the processor can compare the historical service request information with the set judgment conditions to determine the preliminary assessment result. For the first user terminal, whose preliminary assessment result is a normal terminal, authentication is performed based on the first user terminal's historical session key and unique identifier to obtain the authentication result; for the second user terminal, whose preliminary assessment result is suspected of being malicious, final verification is performed to obtain the terminal assessment result.
[0044] For example, the preliminary assessment result can be determined by the following conditions. If any one or more of the following conditions are met, the user terminal is identified as a suspected malicious user terminal: Condition 1: The target cloud servers requested by the user terminal are concentrated on one or several specific cloud servers; Condition 2: The number of historical requests for cloud server services by the user terminal exceeds a preset threshold for the number of requests within a specific time period; Condition 3: The ratio of the number of times the user terminal has successfully authenticated to the number of times it has failed to authenticate when requesting cloud server services is less than a preset threshold; Condition 4: The number of times the user terminal has failed to authenticate when requesting cloud server services is greater than a preset threshold for the number of brute-force attacks. Furthermore, user terminals that do not meet the above conditions are identified as ordinary user terminals.
[0045] Furthermore, based on the above embodiments, the step of verifying identity based on the unique identifier information of the user terminal and determining the identity verification result may include:
[0046] Based on the unique identifier of the user terminal, temporary unique information is generated for the user terminal to enable the user terminal to generate the first verification parameter; the evidence information generated based on the first verification parameter is confirmed. If the confirmation is correct, the second verification parameter after digital signature and the verification timestamp information are determined and sent to the user terminal to enable the user terminal to determine the third verification parameter; based on the third verification parameter and the evidence information, the fourth verification parameter is determined; if the third verification parameter and the fourth verification parameter are equal, the identity verification result is passed; otherwise, the identity verification result is failed.
[0047] In this embodiment, temporary uniqueness information can be understood as data with a unique identifier under the current request period or other periods. The first verification parameter, second verification parameter, third verification parameter, and fourth verification parameter are verification parameters generated according to different information and applied to the user terminal for identity verification. Evidence storage information can be understood as data with evidentiary value that is solidified and stored through technical means; the core objective is to ensure that the information is authentic, complete, and traceable.
[0048] Specifically, the user terminal can generate registration request parameters based on unique identification information combined with the initial user terminal private key, the user terminal's preset key value, and timestamp. The processor can randomly generate temporary unique information for the user terminal based on the registration request parameters, enabling the user terminal to generate first verification parameters based on the temporary unique information, unique identification information, registration request parameters, and timestamp, and determine the digital signature information of the first verification parameters. The processor can generate evidence storage information for the user terminal based on the digital signature information, and confirm the evidence storage information. If the confirmation is correct, the processor can digitally sign the second verification parameters and verification timestamp information and send them to the user terminal, enabling the user terminal to determine the third verification parameter based on the digitally signed first verification parameter and timestamp information; and determine the fourth verification parameter based on the third verification parameter and evidence storage information. If the third verification parameter and the fourth verification parameter are equal, the authentication result is successful; otherwise, the authentication result is unsuccessful.
[0049] For example, a user terminal can generate its unique identifier information based on a unique identity, randomly generated restricted secret information, and a public key, according to the following calculation method:
[0050]
[0051] in, This represents the unique identification information of the user terminal; This represents randomly generated restricted secret information; This indicates the preset cryptographic hash function. This represents the public key of the user terminal. The public key of the user terminal can be calculated based on the initial private key arbitrarily set by the user terminal and a preset elliptic curve as follows:
[0052]
[0053] in, This represents the initial private key of the user terminal, which is arbitrarily set by the user terminal. This represents a preset elliptic curve.
[0054] It should be noted that the reason for calculating the unique identification information of the user terminal in this invention, instead of directly sending an authentication request to the cloud platform based on the unique identity of the user terminal, is to avoid the leakage and attack of the user terminal's identity information.
[0055] After generating its unique identifier, the user terminal generates registration request parameters based on the unique identifier, the initial private key, the user terminal's preset key value, and the timestamp, as follows:
[0056]
[0057] in, This represents the registration request parameters; This represents the default key value of the user terminal; This represents the timestamp of the user's terminal.
[0058] The user terminal sends a user terminal registration request to the verification platform in the cloud computing network according to the registration request parameters. The user terminal registration request includes the following information:
[0059]
[0060] in, This represents the default key of the equivalent user terminal.
[0061] After receiving a user terminal registration request from the user terminal, the verification platform in the cloud computing network where the processor is located randomly generates temporary unique information for the user terminal. The system then sends this temporary unique information to the user terminal. Upon receiving the temporary unique information, the user terminal determines its first verification parameter based on the temporary unique information, the user terminal's unique identifier, registration request parameters, timestamp, and other information, according to the following calculation method:
[0062]
[0063] in, This represents the first authentication parameter of the user terminal; This represents temporary, unique information randomly generated by the user terminal.
[0064] The user terminal determines the digital signature information of the first verification parameter according to the first verification parameter and other information in the following manner:
[0065]
[0066] in, This represents the digital signature information of the first verification parameter.
[0067] After the user terminal determines the digital signature information of the first verification parameter, it generates the user terminal's evidence storage information in the following manner and sends the evidence storage information to the verification platform in the cloud computing network:
[0068]
[0069] in, This indicates the evidence storage information of the user terminal.
[0070] After receiving the evidence storage information from the user terminal, the verification platform in the cloud computing network first confirms the information. If the confirmation is correct, the verification platform in the cloud computing network determines the digital signature information and verification timestamp information of the verification platform according to the following calculation method:
[0071] ;
[0072]
[0073] in, This indicates the digital signature information used by the verification platform; This indicates the verification timestamp information;
[0074] The verification platform in the cloud computing network verifies the second verification parameter based on the verification platform's digital signature information. and verify timestamp information A digital signature is generated, and the digitally signed second verification parameter and verification timestamp information are sent to the user terminal. After receiving the digitally signed second verification parameter and verification timestamp information, the user terminal determines the third verification parameter according to the following calculation method and sends the third verification parameter to the verification platform in the cloud computing network:
[0075]
[0076] Where Y represents the third verification parameter.
[0077] After receiving the third verification parameter, the verification platform in the cloud computing network calculates the fourth verification parameter according to the pre-stored evidence information, the verification platform's digital signature information, and the verification timestamp information, in the following calculation method:
[0078]
[0079] If the third verification parameter is equal to the fourth verification parameter, the user terminal is considered to have passed authentication, and the authentication result is successful. Otherwise, the user terminal is considered to have failed authentication, and the user is refused access to send user requests to the target cloud server. When the user terminal passes authentication, a specific session key generated for the user terminal is sent to the user terminal, and the information corresponding to the user terminal is registered with the cloud computing network platform so that the user terminal can send user service requests to the cloud server based on the session key.
[0080] Based on the above embodiments, the steps for final verification of the second user terminal, which is initially assessed as potentially malicious, to obtain the terminal assessment result can be refined as follows:
[0081] Based on the historical access records in the historical service access information of the second user terminal, determine the access details information of the current request; based on the historical access count, historical authorized parameter information, historical leakage count, and historical unauthorized access information in the historical access information, determine the security-related parameter information; based on the access details information and the security-related parameter information, determine the aggregated evaluation parameters; based on the aggregated evaluation parameters, determine the terminal evaluation result of the second user terminal.
[0082] In this embodiment, historical service access information can be understood as the access status of the cloud server corresponding to the historical access processor. Historical access records can be understood as the historical access status of the service / data currently requested by the user terminal. Access details information is used to characterize the uncertainty of the service / data currently requested. Historical access count can be understood as the number of times the service / data was accessed in the past. Historical authorization parameter information can be understood as the historical authorization status. Historical leakage count can be understood as the number of times data was leaked in the past. Historical unauthorized access information can be understood as information related to historical attempts to access unauthorized services / data. Security-related parameter information can be understood as parameter information related to access security. Aggregated evaluation parameters can be understood as the result after integrating all evaluation parameters.
[0083] Specifically, the processor can determine the access details of the current request based on the historical access records in the historical service access information of the second user terminal. The processor can determine security-related parameters based on the number of historical accesses, historical authorized parameters, historical leaks, and historical unauthorized access information in the historical access information; and determine aggregated evaluation parameters based on the access details and security-related parameters. The processor can then determine the user terminal's access intent based on the aggregated evaluation parameters and determine the terminal evaluation result of the second user terminal.
[0084] For example, the processor can determine whether the service / data currently requested by the user terminal is a previously accessed service / data or an unknown record based on the user terminal's historical access records, and thus determine the uncertainty of the service / data currently requested by the user terminal according to the following calculation method to obtain access details information:
[0085]
[0086] in, This indicates the user terminal's access details. In this scheme, as shown in the above equation, if the service / data currently requested by the user terminal is a service / data that has been accessed in the past, the uncertainty is 0; conversely, if the service / data currently requested by the user terminal is not a service / data that has been accessed in the past, the uncertainty is 1.
[0087] Based on the above embodiments, the steps for determining security-related parameter information based on the number of historical accesses, historical authorized parameter information, number of historical leaks, and historical unauthorized access information in the historical access information can be refined as follows:
[0088] Based on the number of historical accesses, determine the access security parameters; based on the number of historical leaks and the total amount of data accessed within a preset time period, determine the attack factor; based on historical unauthorized access information, determine the unauthorized access parameters; and use the access security parameters, attack factor, and unauthorized access parameters as security-related parameter information.
[0089] In this embodiment, access security parameters are used to characterize whether the user terminal's access behavior is authorized. Attack factors can be understood as characterizing whether the user terminal poses an attack risk. Unauthorized access parameters can be understood as indicating whether there is a risk of accessing unauthorized services / data.
[0090] Specifically, the processor can determine the user terminal's authorization parameters based on historical access counts and preset weighting coefficients, and then use these authorization parameters to determine the user terminal's access security parameters. The processor can also determine whether a user terminal possesses attack factors that pose an attack risk based on historical data leaks and the total amount of data accessed by the terminal within a preset time period. Furthermore, the processor can determine unauthorized access parameters based on historical unauthorized access information, and combine access security parameters, attack factors, and unauthorized access parameters as security-related parameter information.
[0091] For example, the processor can determine the authorization parameter information of the user terminal based on the number of historical service / data accesses of the user terminal and the preset weight coefficient of the service / data, according to the following calculation method:
[0092]
[0093] in, This indicates the authorization parameter information for the user terminal; This indicates the number of services / data accessed by the user terminal in the past; This represents the preset weighting coefficient for historical access services / data. This indicates the services / data accessed in the past.
[0094] The processor can determine the security parameters for the user terminal to access the cloud server where the processor is located, based on the user terminal's historical authorization parameter information, in the following manner:
[0095]
[0096] in, This indicates the security parameters for user terminals accessing cloud servers; Indicates user terminal i; This indicates the number of services / data accessed by the user terminal in the past; This indicates the services or data accessed by the user's terminal in the past.
[0097] The processor can determine the total number of malicious distributions to a user terminal based on the user terminal's historical access to services or data and the number of historical data leaks to the user terminal within a preset time interval, in the following manner:
[0098]
[0099] in, This represents the total number of malicious distributions on user terminals; This represents the number of times user terminal i has data leaked within a preset time interval; t represents the preset time interval.
[0100] The processor can determine the attack factor of a user terminal based on the total amount of data accessed by the user terminal within a preset time period and the total number of malicious distributions from the user terminal, as follows:
[0101] ;
[0102]
[0103] in, This indicates the attack factor of the user terminal; This represents the total number of malicious distributions on user terminals; This indicates the total amount of data accessed by the user terminal within a preset time period. Based on experimental experience, a predefined value of 0.5 can be considered.
[0104] The processor can determine the data leakage frequency of the user terminal using the following calculation method, and use this to determine the unauthorized access parameters:
[0105] ;
[0106]
[0107] in, This indicates the frequency of data leakage on user terminals; It can be predefined as 0.3 based on actual work experience; This represents the unauthorized service / data that the i-th user terminal attempted to access; This indicates the time information of when the i-th user terminal attempted to access unauthorized services / data beyond the j-th time period. This indicates that the parameter was accessed without authorization.
[0108] The aggregated parameter information is obtained by aggregating the evaluation parameter information calculated based on the above steps. Then, determine the user terminal's access intent, and finally determine whether the user terminal is a genuine malicious terminal based on the user's access intent.
[0109]
[0110] in, This represents aggregated information obtained by aggregating information from various evaluation parameters.
[0111] ;
[0112]
[0113] in, This indicates the user terminal's access intent behind accessing the target cloud server. In this invention, if... This indicates that the user terminal is actually a non-malicious user terminal; conversely, if This indicates that the user terminal is actually a malicious user terminal.
[0114] As a first optional embodiment of this example, the training steps of the pre-trained attack identification model may include:
[0115] Obtain a training sample set and an initial attack identification model. The training sample set consists of the differential distribution information between access behavior information of malicious user terminals and non-malicious user terminals. Construct a hyperparameter sequence based on the hyperparameters of the initial attack identification model and determine the objective function of the initial attack identification model. Train the initial attack identification model based on the training sample set and the objective function, and estimate the fitness value of the hyperparameter sequence until the training termination condition is met, thus obtaining a pre-trained attack identification model.
[0116] In this embodiment, the initial attack identification model can be understood as an untrained network model with classification or identification capabilities. The attack identification model needs to contain at least three distinct layers: an input layer, a hidden layer, and an output layer. The input layer receives cloud server access behavior information data from the user terminal to be identified as input and forwards it to the hidden layer of the attack identification model. The hidden layer is the core of the attack identification model, used to identify the differences between the cloud server access behavior information of the user terminal to be identified and normal / malicious data patterns. Finally, the output layer performs a classification task based on the patterns learned from the input data samples. The hyperparameter sequence can be understood as an ordered set of hyperparameters. The objective function can be understood as a non-negative real-valued function in machine learning that measures the difference between the model's predicted values and the true values, used to guide model parameter optimization; it is also called the cost function or loss function. The fitness value can be understood as a quantitative indicator used to evaluate the model's performance on a specific task.
[0117] Specifically, the processor can acquire a training sample set and an initial attack identification model. The training sample set consists of the differential distribution information between access behavior information from malicious and non-malicious user terminals. Based on the hyperparameters of the initial attack identification model (such as weights, biases, learning rate, and the number of hidden units), a hyperparameter sequence is constructed, and the objective function of the initial attack identification model is determined. The processor can train the initial attack identification model based on the training sample set and the objective function, determining the fitness value of each hyperparameter in the hyperparameter sequence until the training termination condition is met, thus obtaining a pre-trained attack identification model.
[0118] For example, the difference distribution information between cloud server access behavior information of non-malicious user terminals and cloud server access behavior information of malicious user terminals can be determined first in the following manner, and used as training samples for the attack identification model:
[0119]
[0120] in, This indicates the difference distribution information between cloud server access behavior information of non-malicious user terminals and cloud server access behavior information of malicious user terminals. This indicates cloud server access behavior information of the user terminal to be identified; The standard deviation of cloud server access behavior information representing historical non-malicious user terminals; This represents the average value of historical cloud server access behavior information for non-malicious user terminals. This indicates information about the cloud server access behavior of malicious user terminals.
[0121] After determining the training samples, the output and parameters of the attack identification model are further determined. The input layer consists of one neuron for each variable in the cloud server access behavior information of the user terminal to be identified. These neurons forward their values to neurons in the hidden layer. The hidden layer consists of multiple neurons, each containing a point-centered feedforward neural system. Each feedforward neural system neuron has a prototype vector (neuron center), which equates the input data to its prototype. The comparison results range between 0 and 1. The output of the initial attack identification model can be represented as follows:
[0122]
[0123] in, This represents the output of the initial attack identification model, including both malicious and non-malicious network attacks; n represents the number of neurons in the hidden layer; and w represents the weights of the output layer.
[0124] In this invention, the main focus when determining the model parameters of the initial attack identification model is to determine the optimal values of these parameters to make the training process more efficient and simpler. The specific optimization process includes four steps: initialization, fitness evaluation, exploration and development, and parameter selection. First, the hyperparameters of the initial attack identification model are initialized, including weights, bias, learning rate, number of hidden units, etc., resulting in the hyperparameter sequence of the initial attack identification model:
[0125]
[0126] in, This represents the total number of hyperparameter sequences in the initial attack identification model; Specifically, the hyperparameters of the initial attack identification model are determined; secondly, the fitness value for each hyperparameter set is determined. Before fitness evaluation, an objective function is defined for optimization, which aims to improve the training and prediction performance of the initial attack identification model.
[0127]
[0128] in, Represent the objective function; This represents maximizing the accuracy of the initial attack identification model.
[0129] Secondly, exploration and development are conducted to determine the solution space of the parameters and update their values to meet the optimization objective. During this stage, the hyperparameters of the initial attack detection model can be randomly modified, such as weights, bias, learning rate, and number of hidden units, to obtain an updated sequence of hyperparameters.
[0130]
[0131] in, This represents the updated hyperparameter sequence; This indicates the current value of the hyperparameters of the initial attack detection model; This represents the optimal values of the hyperparameters of the initial attack detection model; and This represents the range of random vectors from 0 to 1.
[0132] Then, the following sequence of hyperparameters for the initial attack identification model can be determined as follows: The following sequence of hyperparameters is the sequence of hyperparameters that updates parameters following other hyperparameter sequences.
[0133]
[0134] Finally, the fitness value of the hyperparameter sequence following each updated parameter is estimated to find the optimal sequence. In this invention, the hyperparameter sequence with the largest fitness value is selected for the initial attack identification model parameter design. This optimization process is repeated until the initial attack identification model reaches maximum convergence or maximum number of iterations. When the initial attack identification model reaches maximum convergence or maximum number of iterations, the difference distribution information between the cloud server access behavior information of non-malicious user terminals and the cloud server access behavior information of malicious user terminals is input into the initial attack identification model with the completed model parameter settings for training, resulting in a trained attack identification model.
[0135] The technical solution of this invention employs different authentication methods for different user terminals before they access the cloud server. Furthermore, the number of failed authentication attempts can be considered during the authentication process. This prevents malicious user terminals from repeatedly trying password combinations through brute-force attacks to illegally gain system access and subsequently steal data or engage in other malicious activities. It can simultaneously perform comprehensive attack detection on various network attacks in the cloud computing network, such as botnets, DDoS attacks, and brute-force attacks. Compared to existing technologies that are designed and optimized only for specific types of attacks, this solution comprehensively covers all possible attack types, avoiding the omission of some covert or hybrid attacks, thus ensuring more accurate attack identification results. For authenticated user terminals or non-malicious user terminals, their cloud server access behavior information can be obtained. This information is then input into a preset attack identification model for secondary network attack identification to obtain the identification result. In this way, compared with existing technologies that rely solely on the IP address of the request sending server for identification and interception, a wider range of network behavior patterns of user terminals can be explored, preventing attackers from circumventing detection by simulating normal user behavior or using more complex attack strategies, thereby improving identification accuracy.
[0136] Example 2
[0137] Figure 2 This is a schematic diagram of a network attack identification device provided in Embodiment 2 of the present invention. Figure 2 As shown, the device includes:
[0138] Request acquisition module 21 is used to determine the historical request status of the user terminal when it receives a user request sent by the user terminal;
[0139] The first determining module 22 is used to determine the identity verification result and the terminal evaluation result based on the historical request information, the unique identification information of the user terminal and the historical service request information. The terminal evaluation result includes evaluating the user terminal as an ordinary user terminal or a malicious user terminal.
[0140] The second determining module 23 is used to perform secondary network attack identification on the user terminal whose authentication result is passed and the ordinary user terminal based on the pre-trained attack identification model, and determine the identification result.
[0141] The technical solution of this invention involves determining the user terminal's historical request history upon receiving a user request; determining the authentication result and terminal evaluation result based on the historical request history, the user terminal's unique identifier, and historical service request information. The terminal evaluation result includes classifying the user terminal as a normal user terminal or a malicious user terminal; and performing secondary network attack identification on user terminals with successful authentication and normal user terminals based on a pre-trained attack identification model to determine the identification result. This achieves more comprehensive attack type identification, avoids missing some covert or hybrid attacks, and thus ensures more accurate attack identification results.
[0142] Furthermore, the first determining module 22 includes:
[0143] The first submodule is used to perform identity verification based on the unique identifier information of the user terminal and determine the identity verification result if the historical request is the first service request.
[0144] The second submodule is used to determine a preliminary evaluation result based on the historical service request information if the historical request is not the first service request.
[0145] The third submodule is used to perform identity verification on the first user terminal, whose preliminary assessment result is a normal terminal, based on the historical session key and unique identification information of the first user terminal, and obtain the identity verification result.
[0146] The fourth submodule is used to perform final verification on the second user terminal that is suspected of being malicious in the preliminary assessment, and to obtain the terminal assessment result.
[0147] Furthermore, the first sub-module includes:
[0148] The first determining unit is configured to generate temporary uniqueness information for the user terminal based on the unique identifier information of the user terminal, so that the user terminal generates the first verification parameter;
[0149] The second determining unit is used to confirm the evidence information generated based on the first verification parameter. If the confirmation is correct, it determines the second verification parameter and verification timestamp information after digital signature and sends them to the user terminal so that the user terminal can determine the third verification parameter.
[0150] The third determining unit is used to determine the fourth verification parameter based on the third verification parameter and the evidence storage information;
[0151] The fourth determining unit is configured to determine the identity verification result as passed if the third verification parameter and the fourth verification parameter are equal.
[0152] The fifth determining unit is used to determine that otherwise, the authentication result is unsuccessful.
[0153] The fourth sub-module includes:
[0154] The fifth determining unit is used to determine the access details information of the current request based on the historical access records in the historical service access information of the second user terminal;
[0155] The sixth determining unit is used to determine security-related parameter information based on the number of historical accesses, historical authorized parameter information, number of historical leaks, and historical unauthorized access information in the historical access information.
[0156] The seventh determining unit is used to determine the aggregate evaluation parameters based on the access details information and the security-related parameter information;
[0157] The eighth determining unit is used to determine the terminal evaluation result of the second user terminal based on the aggregated evaluation parameters.
[0158] Specifically, the sixth determining unit is used for:
[0159] Determine access security parameters based on historical access volume;
[0160] The attack factor is determined based on the number of historical leaks and the total amount of data accessed within a preset time period;
[0161] Based on the aforementioned historical unauthorized access information, determine the unauthorized access parameters;
[0162] The access security parameters, the attack factors, and the unauthorized access parameters are used as security-related parameter information.
[0163] Optionally, the device further includes a model training module, specifically used for:
[0164] Obtain a training sample set and an initial attack identification model. The training sample set consists of the differential distribution information between access behavior information of malicious user terminals and non-malicious user terminals.
[0165] Based on the hyperparameters of the initial attack identification model, a hyperparameter sequence is constructed, and the objective function of the initial attack identification model is determined.
[0166] The initial attack identification model is trained based on the training sample set and the objective function, and the fitness value of the hyperparameter sequence is estimated until the training termination condition is met, thus obtaining the pre-trained attack identification model.
[0167] The network attack identification device provided in this embodiment of the invention can execute the network attack identification method provided in any embodiment of the invention, and has the corresponding functional modules and beneficial effects of the method.
[0168] Example 3
[0169] Figure 3 A schematic diagram of an electronic device 40 that can be used to implement embodiments of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.
[0170] like Figure 3 As shown, the electronic device 40 includes at least one processor 41 and a memory, such as a read-only memory (ROM) 42 or a random access memory (RAM) 43, communicatively connected to the at least one processor 41. The memory stores computer programs executable by the at least one processor. The processor 41 can perform various appropriate actions and processes based on the computer program stored in the ROM 42 or loaded from storage unit 48 into the RAM 43. The RAM 43 may also store various programs and data required for the operation of the electronic device 40. The processor 41, ROM 42, and RAM 43 are interconnected via a bus 44. An input / output (I / O) interface 45 is also connected to the bus 44.
[0171] Multiple components in electronic device 40 are connected to I / O interface 45, including: input unit 46, such as keyboard, mouse, etc.; output unit 47, such as various types of monitors, speakers, etc.; storage unit 48, such as disk, optical disk, etc.; and communication unit 49, such as network card, modem, wireless transceiver, etc. Communication unit 49 allows electronic device 40 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0172] Processor 41 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 41 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 41 performs the various methods and processes described above, such as network attack identification methods.
[0173] In some embodiments, the network attack identification method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 48. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 40 via ROM 42 and / or communication unit 49. When the computer program is loaded into RAM 43 and executed by processor 41, one or more steps of the network attack identification method described above may be performed. Alternatively, in other embodiments, processor 41 may be configured to perform the network attack identification method by any other suitable means (e.g., by means of firmware).
[0174] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0175] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0176] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0177] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0178] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or middleware components (e.g., application servers), or frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.
[0179] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.
[0180] In one embodiment, the present invention further includes a computer program product, which includes a computer program that, when executed by a processor, implements the network attack identification method of any embodiment of the present invention.
[0181] In implementing the computer program product, computer program code for performing the operations of this invention can be written in one or more programming languages or a combination thereof. Programming languages include object-oriented programming languages such as Java, Smalltalk, and C++, as well as conventional procedural programming languages such as C or similar languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0182] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.
[0183] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.
Claims
1. A method for identifying network attacks, characterized in that, include: When a user request is received from a user terminal, the historical request history of the user terminal is determined. Based on the historical request information, the unique identifier information of the user terminal, and the historical service request information, the identity verification result and the terminal evaluation result are determined. The terminal evaluation result includes evaluating the user terminal as an ordinary user terminal or a malicious user terminal. Based on the pre-trained attack identification model, a secondary network attack identification is performed on the user terminal whose authentication result is passed and the ordinary user terminal to determine the identification result.
2. The method according to claim 1, characterized in that, The step of determining the authentication result and terminal evaluation result based on the historical request information, the unique identifier information of the user terminal, and the historical service request information includes: If the historical request is the first service request, then the user terminal's unique identifier is used to verify the identity and determine the authentication result. If the historical request is not the first service request, then a preliminary assessment result is determined based on the historical service request information; For the first user terminal whose preliminary assessment result is a normal terminal, the authentication result is obtained by performing authentication based on the historical session key and unique identification information of the first user terminal; The second user terminal, which was initially assessed as potentially malicious, was then subjected to final verification to obtain the terminal assessment result.
3. The method according to claim 2, characterized in that, The step of verifying identity based on the unique identifier information of the user terminal and determining the identity verification result includes: Based on the unique identifier information of the user terminal, temporary unique information is generated for the user terminal so that the user terminal can generate the first verification parameter; The evidence information generated based on the first verification parameter is confirmed. If the confirmation is correct, the second verification parameter and verification timestamp information after digital signature are determined and sent to the user terminal so that the user terminal can determine the third verification parameter. The fourth verification parameter is determined based on the third verification parameter and the evidence storage information; If the third verification parameter and the fourth verification parameter are equal, the identity verification result is successful. Otherwise, the authentication result is unsuccessful.
4. The method according to claim 2, characterized in that, The final verification of the second user terminal, which was initially assessed as potentially malicious, to obtain the terminal assessment result includes: Based on the historical access records in the historical service access information of the second user terminal, determine the access details information of the current request; Based on the historical access count, historical authorized parameter information, historical leakage count, and historical unauthorized access information in the historical access information, determine the security-related parameter information; Based on the access details information and the security-related parameter information, determine the aggregation evaluation parameters; Based on the aggregated evaluation parameters, the terminal evaluation result of the second user terminal is determined.
5. The method according to claim 4, characterized in that, The step of determining security-related parameter information based on the historical access count, historical authorized parameter information, historical leakage count, and historical unauthorized access information in the historical access information includes: Determine access security parameters based on historical access volume; The attack factor is determined based on the number of historical leaks and the total amount of data accessed within a preset time period; Based on the aforementioned historical unauthorized access information, determine the unauthorized access parameters; The access security parameters, the attack factors, and the unauthorized access parameters are used as security-related parameter information.
6. The method according to claim 1, characterized in that, The training steps of the pre-trained attack identification model include: Obtain a training sample set and an initial attack identification model. The training sample set consists of the differential distribution information between access behavior information of malicious user terminals and non-malicious user terminals. Based on the hyperparameters of the initial attack identification model, a hyperparameter sequence is constructed, and the objective function of the initial attack identification model is determined. The initial attack identification model is trained based on the training sample set and the objective function, and the fitness value of the hyperparameter sequence is estimated until the training termination condition is met, thus obtaining the pre-trained attack identification model.
7. A network attack identification device, characterized in that, include: The request acquisition module is used to determine the historical request status of the user terminal when it receives a user request sent by the user terminal. The first determining module is used to determine the identity verification result and the terminal evaluation result based on the historical request information, the unique identification information of the user terminal and the historical service request information. The terminal evaluation result includes evaluating the user terminal as an ordinary user terminal or a malicious user terminal. The second determining module is used to perform secondary network attack identification on the user terminal whose authentication result is passed and the ordinary user terminal based on the pre-trained attack identification model, and to determine the identification result.
8. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the network attack identification method according to any one of claims 1-6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that are used to cause a processor to execute the network attack identification method according to any one of claims 1-6.
10. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the network attack identification method according to any one of claims 1-6.